Step 1: Make EMS to where it's reachable from the public Internet using the same name as it has on the internal network (ie: ems.domain.com)
Step 2: Setup an on-net and an off-net profile on EMS. The on-net profiles allows traffic to come back through the tunnel and the web filter sand app firewall are not as strict. The off-net profile (the one the get when at home) has everything blocked in web filter and app firewall.
EMS will determine off-net and on-net by the machines current IP address so you will have a little to do there but not bad